MALICIOUS — dunosag.pdf
MALICIOUS — dunosag.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
28272b62de34574e0ef7067736a40c3140bb99f0c1cf42e19db3c83bf4b7ee5e - SHA-1:
a50202fe4e86a68112d5fb14304608d37d0fca38 - MD5:
c9742b801b005531d7224e365e50a97e - ssdeep:
1536:RtC0g0StfsJXifL9Dk5mtviaOzTd/hoAnHW5A1Wc+LtlhreLWepOy/i+OQXmIRBa:KlCwj9ptvydSAnEAZ/Iyqdk3IT/ - TLSH:
T1843AB0F311A7DD5C3687AF4365BB2268758BD3982262DBA001C8B63C987C67DBF10950 - Submitted as: dunosag.pdf
- File type: pdf · Size: 97314 bytes
- Verdict: malicious (92/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://www.bouldersudbury.org/wp-content/plugins/formcraft/file-upload/server/content/files/1609c9d27ccc9e---9881344401.pdf, https://raiporjai.com/piceditor/file/28264568223.pdf, https://www.partyshuttlebus.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16080b1d386ba8---kedodaxofigaji.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/DOqCt-cVA4I/uplcv?utm_term=movavi+pdf+editor+2.4.0
- https://www.bouldersudbury.org/wp-content/plugins/formcraft/file-upload/server/content/files/1609c9d27ccc9e---9881344401.pdf
- https://raiporjai.com/piceditor/file/28264568223.pdf
- https://www.partyshuttlebus.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16080b1d386ba8---kedodaxofigaji.pdf
- http://imailbox.nl/images/uploadedimages/file/tugesivime.pdf
- http://como.gattinonimondodivacanze.it/themes/userfiles/files/48964787579.pdf
- http://aaexpansionjoint.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609f253218bfd---48143126741.pdf
- https://nezamirekhaseafoods.com/userfiles/file/kufefebedarebona.pdf
- https://dermo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c73c574ecd3---63478427532.pdf
- https://clifestyle.net/uploades/userfiles/file/pogagatinoxabibubivodono.pdf
- http://zulaikhatextile.com/userfiles/files/lipefewajunolewazoluv.pdf
- http://haumeaonline.com/userfiles/file/39131306469.pdf
- http://terminsk.by/pics/files/nujifafurugara.pdf
- https://lncl.org/ckfinder/userfiles/files/23693605303.pdf
- http://evabody.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1606f5fa010081---43220377129.pdf
- http://sns.hu/_user/file/95394900459.pdf
- http://lycee-elm.info/userfiles/file/40634875802.pdf
- http://www.dadosefatos.net.br/wp-content/plugins/formcraft/file-upload/server/content/files/1606cc9d5b1ad5---lezadipefukeguweworinitol.pdf
- http://geology.ie/wp-content/plugins/formcraft/file-upload/server/content/files/160c916dc2251a---zojarunomoxipezikefisez.pdf
- http://sumnerclassof1976.com/clients/4/49/49b54eafcc86ae0c30eb104ab8b91c7c/File/8255067627.pdf
- https://webvitamin.vn/app/webroot/uploads/files/xagilovexunokowizo.pdf
- https://mfdesign.hu/files/file/xusuwawuxesizibozur.pdf
- https://mokshadhamnepal.org/userfiles/files/73031753553.pdf
- http://truhlarstvisollner.cz/data/file/72882316068.pdf
- http://www.tif.cn/wp-content/plugins/super-forms/uploads/php/files/6hahpmrcse0timp0cnohsopnt5/26999944193.pdf
Embedded domains
- feedproxy.google.com
- www.bouldersudbury.org
- raiporjai.com
- www.partyshuttlebus.com.au
- imailbox.nl
- como.gattinonimondodivacanze.it
- aaexpansionjoint.com
- nezamirekhaseafoods.com
- dermo.com
- clifestyle.net
- zulaikhatextile.com
- haumeaonline.com
- lncl.org
- lycee-elm.info
- www.dadosefatos.net.br
- sumnerclassof1976.com
- mokshadhamnepal.org
- www.tif.cn
- saothienemb.com
- tamlaproject.com
- www.w3.org
- purl.org
- ns.adobe.com
- terminsk.by
- evabody.ro
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report